[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Spoofed email



By the way sorry for not showing up yesterday. Due to mixure of apt
repositories, I had to reinstall my machine (and even lost data :(, 

As for spoofed e-mails, I think that the page
http://eleccomm.ieee.org/header-spoofing.shtml sums our problem now, and it
seems that this is a common thing done by viruses (like Beagle).

While I solve my problems, please have a look at this e-mail:
http://mail.python.org/pipermail/mailman-users/2004-May/036515.html
They say you need to USE_ENVELOPE_SENDER=1 in mailman's Default.py to make it
depend on the envelope From. This is 'how to get both programs to use the same
>From field part'.

--- Nadim Shaikli <shaikli at yahoo dot com> wrote:
> I don't think reverse DNS is a realistic option.  Up until a few months
> back (until we moved to our current machine/hosting facility) arabeyes
> would not resolve on a reverse DNS query and I'm guessing alot of our
> members' emails would simply not be accepted.  I don't believe
> this is a path we should pursue (M.Sameer is not a unique person in
> this - he simply spoke up because he knows what it means :-).

And I do:)~ I already knew that it will probably not be accepted. I wouldn't
say it is not the RW(tm) though, and I believe the members with this problem
are not too many.

>  I do
> think that we need to put the right brakes on postfix to never accept
> incoming mail with @arabeyes.org on it both on the envelope (already
> happening) and on the From: header (this is the part that needs to be
> added).  The postfix docs note how to minimal header parsing, I'm just
> too dense to know how to do it - see previous post on this topic from
> me with the appropriate URL to read.
> 

Speaking more practically, I will figure it out this night. I will explain it
by e-mail as I will not be able to access irc then. If I understand correctly
we need a check that rejects any e-mail which has different From headers.


Salam,
Muhammad Alkarouri


	
		
__________________________________
Do you Yahoo!?
Win a $20,000 Career Makeover at Yahoo! HotJobs  
http://hotjobs.sweepstakes.yahoo.com/careermakeover